Search by job, company or skills

Application Security Engineer

  • Posted 4 hours ago
  • Be among the first 10 applicants

Job Description

The Role

DevSecOps Pipeline Design & Implementation

  • Design, build and maintain secure CI/CD pipelines integrating SAST, DAST, SCA, secrets detection, container scanning and SBOM generation as automated, non-blocking gates that shift security feedback to the point of code commit.
  • Implement and tune security tooling (GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP, IriusRisk or equivalent) in collaboration with ICS and the COE, balancing coverage against pipeline velocity.
  • Define pipeline security standards, guardrails and paved-road templates that delivery teams can adopt without bespoke configuration, and maintain them as the threat landscape and tooling evolve.

Security Testing & Vulnerability Management

  • Own the security testing practice for in-scope applications: plan and execute SAST, DAST, penetration testing support and API security testing, and validate remediation of findings through to closure.
  • Triage and prioritise vulnerability findings from automated tooling and manual review, producing clear, risk-rated remediation guidance that engineering teams can act on without specialist interpretation.
  • Track finding closure rates across the top platforms, reporting on open risk and recurring weakness themes to the CoE Lead, and escalating blockers where remediation is stalling.

Secure Coding Enablement & Developer Support

  • Act as the primary hands-on security engineering resource for delivery teams: review pull requests for security weaknesses, pair with engineers on remediation, and provide just-in-time secure coding guidance.
  • Build and maintain a secure coding standards library, covering OWASP, injection, authentication, authorisation, secrets management and cryptographic hygiene, mapped to the technology stacks in use across HWC.
  • Run developer-facing security enablement sessions — secure code reviews, threat modelling walkthroughs, hands-on labs — to build security awareness at the point where vulnerabilities are introduced.

Build Integrity & Supply Chain Security

  • Implement and operate build-integrity controls: artefact signing, provenance verification, dependency allow-listing and licence compliance checks integrated into CI/CD pipelines.
  • Own software composition analysis (SCA) and SBOM generation across in-scope platforms, ensuring dependency and licence risk feeds directly into the technical risk profiling practice.
  • Monitor for new CVEs and zero-day disclosures affecting in-scope technology stacks, assess impact, and coordinate rapid response with platform owners and ICS.

AI-Assisted Security Engineering

  • Apply AI and automation (GenAI, GitHub Copilot, agent frameworks) to security engineering tasks — automated triage, finding summarisation, remediation suggestion, pipeline policy generation — with human-in-the-loop validation on outputs.
  • Evaluate and pilot emerging AI-assisted security tooling in coordination with ICS and the CoE Lead, identifying where automation creates genuine capacity rather than adding cost or noise.
  • Contribute to the CoE's broader AI-enablement programme by converting manual, analyst-dependent security steps into repeatable, tool-assisted engineering workflows.

Cloud Security Engineering

  • Implement and validate Azure cloud security controls — identity and access management, network segmentation, secrets management (Key Vault), container and Kubernetes security, storage and data encryption — aligned to InfoSec and ICS standards.
  • Conduct infrastructure-as-code (IaC) security reviews (Terraform, Bicep or equivalent), identifying misconfiguration risks before they reach production.
  • Support cloud security posture management (CSPM) tooling adoption and alert triage in collaboration with ICS and platform teams.

Cross-COE Integration & Stakeholder Collaboration

  • Work closely with the Threat Modelling & Risk Specialist to ensure threat model findings and technical risk profiles translate into concrete engineering controls and pipeline gates, closing the loop between assessment and implementation.
  • Partner with the Security Architect to implement architectural review recommendations at the code, pipeline and infrastructure level, validating that design-time decisions are reflected in the running system.
  • Collaborate with LOB platform owners, engineering leads and security champions to embed security tooling and practices into team workflows without becoming a dependency or bottleneck.

Governance, Reporting & Continuous Improvement

  • Maintain an up-to-date view of security tooling coverage, pipeline gate effectiveness and finding-closure velocity across in-scope platforms, reporting to the COE Lead on a defined cadence.
  • Identify recurring weaknesses and systemic tooling gaps, recommending and implementing improvements to pipeline controls, scanning rules and developer guidance rather than remediating issues one by one.
  • Support evidence collation for InfoSec, ICS and audit (PwC) reviews, ensuring security engineering controls are documented, demonstrable and traceable to NIST, OWASP and SAMM requirements.

Requirements

Minimum Qualifications

  • 8-12 years in technology, with 5+ years in application security engineering, DevSecOps or a security-engineering role with hands-on pipeline and tooling ownership.
  • Demonstrable experience designing and operating DevSecOps pipelines: SAST, DAST, SCA, secrets detection, container scanning and SBOM generation integrated into CI/CD.
  • Hands-on experience with security tooling (GitHub Advanced Security, Checkmarx, Snyk, Trivy, OWASP ZAP or equivalent) in enterprise engineering environments.
  • Azure cloud security engineering knowledge: IAM, Key Vault, network controls, container/Kubernetes security, IaC scanning.
  • Working knowledge of OWASP Top 10, NIST, secure coding principles and vulnerability management, with ability to translate findings into engineer-ready remediation guidance.

Preferred Qualifications

  • Insurance or financial-services industry experience.
  • Security certifications (CSSLP, CEH, OSCP, GWEB) and/or Azure security certifications (AZ-500, SC-100).
  • Experience applying AI and automation to security engineering (GenAI-assisted triage, agentic pipelines, GitHub Copilot for secure code review).
  • Experience enabling federated engineering teams and security champions at scale, across distributed LOB structures.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 153735319

Similar Jobs

Taguig, Philippines

Skills:

DASTTerraformnetwork securityAzure SecurityDevSecOpsIamContainersKubernetesGenAICloud Security Posture ManagementKey Vaultcontainer scanningsecrets detectionSBOM generationOWASP ZAPSASTTrivyBicepSnykGitHub CopilotSCAInfrastructure-as-CodeCheckmarxGitHub Advanced Security

Beware of Scammers

We don’t charge money for job offers